Vulnerability Description
A Buffer Overflow vulnerability in the khcrypt implementation in Google Earth Pro versions up to and including 7.3.2 allows an attacker to perform a Man-in-the-Middle attack using a specially crafted key to read data past the end of the buffer used to hold it. Mitigation: Update to Google Earth Pro 7.3.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Earth | < 7.3.3 |
Related Weaknesses (CWE)
References
- https://support.google.com/earth/answer/40901Vendor Advisory
- https://support.google.com/earth/answer/40901Vendor Advisory
FAQ
What is CVE-2020-8896?
CVE-2020-8896 is a vulnerability with a CVSS score of 4.2 (MEDIUM). A Buffer Overflow vulnerability in the khcrypt implementation in Google Earth Pro versions up to and including 7.3.2 allows an attacker to perform a Man-in-the-Middle attack using a specially crafted ...
How severe is CVE-2020-8896?
CVE-2020-8896 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8896?
Check the references section above for vendor advisories and patch information. Affected products include: Google Earth.